I'm a Developer Support Engineer at Genpact, which puts me in an odd but useful spot — I spend my days debugging backend services and API behavior, and just as often tracing OAuth misconfigurations and root causes through SIEM logs. The line between "this is a bug" and "this is a security gap" blurs more often than people expect, and I've ended up comfortable working on both sides of it.
That split goes back further than this job. Alongside a full-stack development internship at 42Learn building Java backend modules, I've done three security-focused internships covering digital forensics, data security, and SOC-style log correlation — including hands-on vulnerability assessments across 40+ web application and SQL database endpoints using Burp Suite and OWASP ZAP, where I flagged configuration defects before they shipped.
The thing I'm most proud of came out of that security side: I found an active phishing site impersonating Zoho Corporation, documented it, and reported it. They took the domain down and credited me in writing for the find.
On the development side, I've built a Python vulnerability scanner that automates port scanning, OSINT gathering, and report generation, a cloud-based secure data-sharing framework using role-based access control, and a Java-based password manager — so even my security tooling tends to involve writing actual software, not just running other people's tools.
I'm currently working through the Microsoft SC-200 (Security Operations Analyst) certification and ISC2 CC certification. Given that my day-to-day already sits at the intersection of writing software and securing it, I'm specifically interested in SOC Analyst, Security Engineer and DevSecOps/VAPT related roles, alongside backend/full-stack development and cybersecurity analyst positions — since all four are genuinely represented in what I've actually done, not just what I'd like to try.
